mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-08 02:08:54 +00:00
modifed win_susp_msoffice.yml
This commit is contained in:
parent
fc7f8ecea3
commit
bea2daac45
@ -19,7 +19,8 @@ detection:
|
||||
Image:
|
||||
- '*\powerpnt.exe'
|
||||
- '*\winword.exe'
|
||||
CommandLine: '* "http*'
|
||||
- '*\excel.exe'
|
||||
CommandLine: '* http*'
|
||||
condition: selection
|
||||
level: medium
|
||||
falsepositives:
|
||||
|
Loading…
Reference in New Issue
Block a user